Skip to content
Colour theme
Open tools

How it works

Three unrelated things get called “AI watermarking”. They are stored differently, detected differently, and removed differently. Treating them as one is how tools in this category end up lying to people.

Characters you cannot see

Unicode contains characters that render as nothing at all. A zero-width space (U+200B) occupies no width. The Unicode tag block (U+E0000–U+E007F) maps one to one onto printable ASCII, so a run of tag characters can carry an entire readable message that is completely invisible in any normal editor.

These are deterministic. There is no probability involved: a character is either U+200B or it is not. That makes them the one category this tool can find and remove with certainty.

Removal is context-aware, because several of these characters have legitimate jobs. A zero-width joiner is what holds an emoji sequence together. A zero-width non-joiner changes spelling in Persian and several Indic scripts. Tag characters build the Scotland, Wales and England flag emoji. Those are detected and kept, and the interface says which ones were kept and why.

Open the text tool →

Statistical watermarks in word choice

A model-level watermark does not add anything to the text. As a model generates, a secret keyed rule scores the candidate next tokens using the preceding context and nudges some of them very slightly upward. Each individual choice stays natural and invisible to a reader, but across a long enough passage the pattern of choices carries a statistical signal that a detector holding the matching key can test for.

Because the signal lives in the words themselves, it survives copying and pasting, and it can survive light editing. Heavy rewriting, paraphrasing, translation, or mixing with other writing may weaken it substantially.

What we can say about Claude specifically

Anthropic has published that Claude “weaves an imperceptible watermark directly into the text itself”, applied at the model level, for models launched on or after 2 August 2026. It has said that detection details will follow in forthcoming technical documentation.

Anthropic has since named the scheme: a version of SynthID-Text, the method Google DeepMind published in Nature in 2024. That is enough to know how the mark is put there. It is not enough to read one back, because detection scores the text against values derived from a key Anthropic holds and has not published, so this tool still reports detection as unavailable rather than guessing. Claims elsewhere that Claude simply inserts zero-width characters have no support in that documentation, and contradict its own description of a mark that adds no characters at all.

Knowing the scheme is enough to remove the mark, which is what the text tool does. The mark is carried by the choice of words, so the words are rewritten: sentence by sentence, on a GPU, with each rewrite checked against the original so the meaning, the numbers, the names and the quotations survive. Reading a mark and removing one are different problems, and only the first needs the key.

Anthropic’s documentation

What happens when detection is published

This is the thing most people arrive here wanting, so it is worth being exact about where it stands and what the plan is.

Today

Text, pictures and files all work. SynthID comes out of a picture by redrawing it, the Stable Diffusion mark is removed and measured, Claude’s text mark is removed by rewriting the words on a GPU, and metadata goes with any of them.

Video

A clip is thousands of pictures, so the work is the same and there is a great deal more of it. The page at /app/video lists the options it will carry and what each one still needs.

The hard part is not the model, it is the arithmetic: a minute of footage at thirty frames a second is eighteen hundred separate redraws, and doing that at a price anyone would pay takes work that has not been done yet.

More providers

New marks appear as new tools ship. Each one is added when there is something real to test against rather than when it is announced.

Where a result can be measured, the number is printed next to it. Where it cannot, the page says what was done rather than inventing a score for it.

Invisible watermarks in image pixels

This one is not metadata and it is not a logo drawn on top. The signal is in the pixel values themselves: a pattern of changes too small to see, spread across the whole picture, which a matching detector can still read. That is why it survives being converted to another format, screenshotted, cropped, lightly edited, and stripped of every byte of metadata. No image editor can show it to you.

Four schemes get called by one name and they are not variants of one thing. The mark Stable Diffusion writes by default is open source, so it can be read. It stores each bit as a remainder: a value derived from an 8 by 8 patch of the blue-yellow colour channel is nudged so that dividing it by 36 leaves a remainder above or below halfway. Adding an offset drawn at random from a range exactly one step wide makes that remainder uniform whatever it was, so the decoder is left reading a coin flip. That is a mathematical statement rather than a hopeful one, and because the scheme is public the tool can read the payload before and after and show you both numbers.

SynthID and Stable Signature need something different. Both are trained against exactly what an editor does to a picture: noise, blurring, sharpening, compression. Turning those up does not eventually work, it just damages the picture. What reaches them is redrawing, running the image back through a diffusion model so the fine detail is replaced rather than filtered, and that follows from where the mark lives. Anything that keeps the original fine detail keeps the watermark with it.

What redrawing costs

Fine detail is what gets replaced, and small text is fine detail. A portrait or a landscape usually comes back indistinguishable; a screenshot full of small type is the hard case, and can come back subtly wrong. It is worth a look before you use it.

Removal rewrites pixels, so it reports what that cost, measured against the same picture put through the same warp and nothing else. That comparison is the one that isolates damage: a fraction of a pixel of displacement produces a large raw difference on its own, so measuring against the untouched original would print a frightening number for output that is visually identical. Both figures are shown, and both are labelled.

The image watermark remover runs this, and lists what happens to each scheme.

Metadata and signed provenance in files

Image and document files carry blocks of data alongside the picture. EXIF holds camera settings, GPS coordinates and timestamps. XMP and IPTC hold authorship and captions. ICC holds the colour profile. Each format stores them in a different place: JPEG uses APP marker segments, PNG uses text chunks, WebP uses RIFF chunks, SVG uses XML elements.

Removing them is container surgery. The file is rebuilt without those blocks while the compressed image data is copied across untouched, so the pixels are byte-identical. Two things are deliberately kept unless you ask otherwise: the EXIF orientation flag, because dropping it visibly rotates photos that viewers were auto-rotating, and the ICC profile, because dropping it shifts colour on wide-gamut images.

Content Credentials

C2PA provenance is a different thing again: a manifest containing signed claims about how a file was made, embedded in the file and cryptographically bound to its bytes. When a file carries one, this tool reads who signed it, what tool made it, whether it declares itself AI-generated, and whether the bytes still match the signature.

Two results that look similar mean very different things, so the interface keeps them apart. “The signature is valid and the bytes are unmodified” is a mathematical fact about the file. “The signer is on a recognised trust list” is a separate question, and many genuine files fail it simply because the certificate programme is young. A browser also cannot check certificate revocation, so that is reported as unchecked rather than quietly treated as fine.

Editing a signed file breaks its signature permanently. This tool will tell you before that happens, and it will never re-sign a file or imply that a modified one still carries valid provenance.

Common questions

Can this remove Claude’s text watermark?
Yes. Anthropic weaves the mark into the choice of words rather than into the characters, so deleting invisible characters does nothing to it. It comes out on our GPU instead: the passage is rewritten sentence by sentence, and every rewrite is checked against the original so the meaning, the numbers, the names and the quotations all survive. It is a separate option in the text tool and it costs credits, because it runs a language model.
Do invisible characters mean text was written by AI?
No. Zero-width characters and unusual spaces come from copying between editors, from web pages, from PDF exports, and from ordinary software. They are worth removing before you publish, but their presence says nothing about who or what wrote the text.
Can this remove SynthID from an image?
Yes. SynthID is built to survive noise, blurring and compression, so filtering the pixels never reaches it however hard you push. Instead the picture is redrawn on a GPU at low strength, which replaces the fine detail the mark lives in. It takes a minute or two, and small text can come out slightly malformed.
Does removing metadata reduce image quality?
No. Metadata is removed by rewriting the file container and copying the compressed image data across byte for byte. The picture is never decoded and re-encoded, so the result is pixel-identical to the original.
What happens to Content Credentials if I strip metadata?
The signature breaks permanently and cannot be restored. C2PA signs a hash of the file, so any change outside the manifest’s own region makes validation fail. This tool warns you before it happens and will never re-sign a file.
Are my files uploaded anywhere?
No. Every parser runs in your browser and there is no server-side processing, so there is nowhere for a file to be sent. This page and the focused tool pages do carry Google advertising, which contacts Google but never touches your file. The workspace under /app carries a second content security policy that forbids any outbound request at all, so there the guarantee is enforced by your browser rather than promised by us. The privacy page lists exactly which pages carry advertising.